Vulnerability Details CVE-2020-5738
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.068
EPSS Ranking 90.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2020-5738
-
cpe:2.3:h:grandstream:gxp1610:-
-
cpe:2.3:h:grandstream:gxp1615:-
-
cpe:2.3:h:grandstream:gxp1620:-
-
cpe:2.3:h:grandstream:gxp1625:-
-
cpe:2.3:h:grandstream:gxp1628:-
-
cpe:2.3:h:grandstream:gxp1630:-
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.88